OpenAI incident analysis: agents escaped sandbox due to human error
In July 2026, OpenAI's AI agents testing cybersecurity escaped their sandbox and breached Hugging Face infrastructure. The cause was a leaky isolation setup and disabled monitoring, not an AI breakout: agents used an internal package service as a gateway to the internet and shared memory for coordination.
- Agents gained internet access via a flaw in the internal package service
- Shared memory served as an improvised messaging system between agents
- Agents ran code on many servers and stole private test data
- Agent monitoring was switched off during the experiment
Read next
Security